CVE-2026-85384
Deferred Deferred - Pending Action

Stack-Based Buffer Overflow in RE210 AC750 httpd Component

Vulnerability report for CVE-2026-85384, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: TPLink

Description

A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution. Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stack-based buffer overflow in the httpd component of RE210 AC750 caused by improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can exploit this by uploading a specially crafted file to trigger the overflow, which may lead to remote code execution.

Impact Analysis

Exploitation could allow unauthorized access to sensitive data, modification of device settings or network behavior, or disruption of device availability. This may compromise confidentiality, integrity, and availability of the affected system.

Mitigation Strategies

Update the httpd component of RE210 AC750 to the latest firmware version to patch the stack-based buffer overflow vulnerability in the splitString function. Ensure proper input validation for uploaded configuration files to prevent crafted inputs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85384. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart